CVE-2016-10522

rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:rails_admin_project:rails_admin:*:*:*:*:*:ruby:*:*

Information

Published : 2018-07-05 09:29

Updated : 2019-10-09 16:16


NVD link : CVE-2016-10522

Mitre link : CVE-2016-10522


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

rails_admin_project

  • rails_admin